# Rhysida ransomware lists law firm victim

Published: 2026-09-30 · Severity: elevated
Canonical: https://vorant.io/reports/e8965fb9-bcb7-5e24-8f16-03375882d37b/rhysida-ransomware-lists-law-firm-victim

> Rhysida ransomware group added Law Offices of R. David Williams, P.A. to its leak site, claiming theft of extensive criminal case files.

Ransomware.live has indexed a new victim listing from the Rhysida ransomware group's leak site: Law Offices of R. David Williams, P.A., a criminal defense practice. The listing claims exfiltration of a large volume of sensitive legal data covering roughly 175+ clients, including felony case files, DUI records, probation violation documents, FDLE expungement packets with fingerprint cards, Risk Protection Order records, immigration detention details, and material witness monitoring information. The claimed dataset reportedly includes approximately 206 GB of police discovery material such as bodycam video, 911 recordings, jail calls, incident reports, photo line-ups, and FCIC/NCIC law enforcement database forms, along with victim and witness data protected under Marsy's Law.

No technical details of the intrusion vector, malware behavior, or exploited vulnerabilities are provided in this listing; it is a leak-site entry rather than incident analysis. For defenders, this represents a single confirmed Rhysida victim rather than a new campaign or technique. Organizations handling similarly sensitive legal, law-enforcement, or witness-protection data should treat this as a reminder to review data segmentation, backup integrity, and access controls around case management systems containing highly sensitive personal and investigative records, particularly small legal practices that may lack mature security operations.

## Mentioned in this report

- Threat actors: rhysida
- Malware: Rhysida

Source reporting: https://www.ransomware.live/id/TGF3IE9mZmljZXMgb2YgUi4gRGF2aWQgV2lsbGlhbXMsIFAuQS5Acmh5c2lkYQ==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e8965fb9-bcb7-5e24-8f16-03375882d37b/rhysida-ransomware-lists-law-firm-victim.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
